Experts Across Tech Sector Share Their Views On EU AI Act Changes Coming Into Force
Preparatory obligations related to high-risk AI systems take effect today as the EU AI Act advances towards full implementation. These rules apply to organizations both inside and outside the EU that place AI systems on the EU market or use them within…
Preparatory obligations related to high-risk AI systems take effect today as the EU AI Act advances towards full implementation. These rules apply to organizations both inside and outside the EU that place AI systems on the EU market or use them within the bloc.
The European Commission has stated that the legislation addresses safety and rights risks associated with certain AI applications. According to the Commission, "The AI Act is the world’s first comprehensive law for AI. It aims to address risks to health, safety, and fundamental rights."
High-risk systems include AI used in recruitment screening, credit scoring, healthcare access, educational assessment, and law enforcement. These are applications where automated outputs can significantly impact individual decisions.
The Commission links the law to trust, noting that uneven national rules and legal uncertainties have hindered AI adoption across the EU, necessitating a unified framework.
Provider Obligations for High-Risk AI Systems
Providers must conduct a conformity assessment before placing a high-risk AI system on the market or putting it into service. This assessment evaluates risk management, data governance, technical documentation, transparency, human oversight, accuracy, and cybersecurity.
A quality management system must be maintained throughout the system's lifecycle. Providers are responsible for the system's safety and compliance over its entire lifecycle.
Preparatory obligations related to high-risk AI systems take effect today as the EU AI Act advances towards full implementation.
Each high-risk system must be registered in a public EU database to facilitate market surveillance by authorities. If there are meaningful changes to the system or its intended use, the assessment must be repeated. For AI used as safety components in regulated products, Article 6 requires linkage to third-party product conformity checks.
Responsibilities of Deployers and Public Authorities
Deployers must adhere to usage instructions and monitor system operations in practice. Human oversight should be assigned to staff with the authority to intervene when risks arise.
Public authorities and organizations providing public services must undertake a fundamental rights impact assessment before first use, evaluating effects on rights protected under EU law and data protection obligations.
Individuals affected by AI-supported decisions must be informed. If a decision has legal effects, they can request an explanation, with the Act requiring a "clear and meaningful explanation."
In workplace settings, additional notification duties apply. Employees and workers’ representatives must be informed before deploying high-risk systems.
The Act classifies high-risk AI by intended purpose, with Annex III listing sensitive applications in employment, education, migration, justice, and biometric identification.
Providers may argue that a system listed in Annex III is not high-risk if it performs a narrow or preparatory task and does not influence outcomes. Such assessments must be documented and made available to authorities upon request.
The Commission will provide guidance with practical examples to aid classification, aiming to offer businesses clarity while maintaining protection for health, safety, and fundamental rights.
Penalties for non-compliance include fines of up to €35 million or 7% of global turnover for prohibited practices, with lower thresholds for other breaches.
Based on reporting by techround.co.uk.
